CVE Alert: CVE-2025-10601 – SourceCodester – Online Exam Form Submission

CVE-2025-10601

HIGHNo exploitation known

A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0. Affected is an unknown function of the file /admin/index.php. Such manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS v3.1 (7.3)
Vendor
SourceCodester
Product
Online Exam Form Submission
Versions
1.0
CWE
CWE-89, SQL Injection
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Published
2025-09-17T16:32:10.812Z
Updated
2025-09-17T16:32:10.812Z

AI Summary Analysis

Risk verdict

Why this matters

Most likely attack path

Who is most exposed

Detection ideas

  • Web server and application logs show anomalous input patterns or errors indicative of SQLi attempts against email fields.
  • DB logs reveal unusual SELECT/UPDATE patterns from the web app.
  • IDS/IPS signatures or WAF alerts flagging SQLi payloads targeting admin/index.php.
  • Unusual spikes in database query latency or failed login/permission events from the app host.

Mitigation and prioritisation

  • Apply vendor patch or upgrade to fixed release; verify patch deployment in staging before production.
  • Enforce parameterised queries and input validation on all user inputs, especially email fields.
  • Deploy or tune WAF rules to block standard SQLi patterns reaching the app.
  • Restrict admin/index.php exposure (IP allowlisting, disable direct access if feasible).
  • Change management: perform security testing in a controlled window; rehearse rollback if patch introduces issues. If KEV or EPSS signals were present, escalate to priority 1.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.